<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DLP - how to determine user action upon &amp;quot;ask user&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118495#M16781</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I have rule set up via DLP,&amp;nbsp; to prevent certain data to leave via mail. The rule indeed works as it should.&lt;BR /&gt;&lt;BR /&gt;Since there are false positives possible - i have "ask user" enabled in order to let the user evaluate,&lt;BR /&gt;I need to monitor all the events, in which the user has decided to "send anyway",&lt;BR /&gt;I cant seem to find the relevant log "trigger" to display only dlp incidents where users found the warning to be irrelevant.&lt;BR /&gt;&lt;BR /&gt;Any hints, ideas or down right solutions to my need?&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;&lt;BR /&gt;Peter&lt;/P&gt;</description>
    <pubDate>Mon, 17 May 2021 08:40:46 GMT</pubDate>
    <dc:creator>Peter_Bjeldbak</dc:creator>
    <dc:date>2021-05-17T08:40:46Z</dc:date>
    <item>
      <title>DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118495#M16781</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I have rule set up via DLP,&amp;nbsp; to prevent certain data to leave via mail. The rule indeed works as it should.&lt;BR /&gt;&lt;BR /&gt;Since there are false positives possible - i have "ask user" enabled in order to let the user evaluate,&lt;BR /&gt;I need to monitor all the events, in which the user has decided to "send anyway",&lt;BR /&gt;I cant seem to find the relevant log "trigger" to display only dlp incidents where users found the warning to be irrelevant.&lt;BR /&gt;&lt;BR /&gt;Any hints, ideas or down right solutions to my need?&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;&lt;BR /&gt;Peter&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 08:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118495#M16781</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2021-05-17T08:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118504#M16782</link>
      <description>&lt;P&gt;Custom action for logs (alert) for this rule, and/or specific filters for DLP logs/events&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 09:45:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118504#M16782</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-17T09:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118534#M16787</link>
      <description>&lt;P&gt;Hi - and thx for the reply.&amp;nbsp; The log option is the on i am most keen on - but my problem is, simply put, i cant find the field/value which indicates the user response "send anyway" to the "ask user"&lt;BR /&gt;&lt;BR /&gt;I would like to have the log show ONLY those who have received the choise (those who have sent questionable materiel) AND have chosen to "send&amp;nbsp; anyway"&lt;BR /&gt;&lt;BR /&gt;I have done tests and checked the log subsequently&amp;nbsp; - to no avail &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 13:21:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/118534#M16787</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2021-05-17T13:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119215#M16867</link>
      <description>&lt;P&gt;The end user generally has to provide a reason, which I imagine would go in the logs.&lt;BR /&gt;If you open up a log card on an event, do you see this reason?&lt;BR /&gt;If so, that would be the log field to trigger on.&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 03:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119215#M16867</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-24T03:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119279#M16877</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;As to log entry to use for sorting out certain answers - Unfortunatly not - i can´t seem to find any indication in the log indicating the users choice.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have tried looking at the dlp log upon the time of the user reply to see what gives - to no avail &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;What pussles me is that a premade log option would be logical at the get go&amp;nbsp; - after all - you would want to to able find all users who desides to override the warning.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119279#M16877</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2021-05-25T06:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: DLP - how to determine user action upon "ask user"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119285#M16878</link>
      <description>&lt;P&gt;My desires have been met - i did find the solution and I am sorry to say - right in front of me.&lt;BR /&gt;&lt;BR /&gt;Turns out there actually is a field - which can be&amp;nbsp;&lt;SPAN&gt;Utilised - however i need to use SmartView rather than the log ind smartconsole.&lt;BR /&gt;&lt;BR /&gt;The field "UserCheck response" fits like a glove (i feel stupid not finding this first time around)&lt;BR /&gt;&lt;BR /&gt;Anyway - call of the dogs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-how-to-determine-user-action-upon-quot-ask-user-quot/m-p/119285#M16878</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2021-05-25T06:57:13Z</dc:date>
    </item>
  </channel>
</rss>

